CVE-2026-42287: Emlog: SQL Injection Vulnerability in log_model.php within addLog() and updateLog() Functions
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially leading to complete database compromise, data theft, or system destruction. This issue has been patched in version 2.6.11.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42287?
CVE-2026-42287 is a critical vulnerability that allows SQL injection, which can lead to arbitrary code execution.
How do I fix CVE-2026-42287?
To fix CVE-2026-42287, update Emlog to version 2.6.11 or later.
What components are affected by CVE-2026-42287?
CVE-2026-42287 affects the log_model.php file in Emlog prior to version 2.6.11.
What are the potential impacts of exploiting CVE-2026-42287?
Exploitation of CVE-2026-42287 can allow attackers to execute arbitrary SQL commands and compromise the database.
Is there a known exploit for CVE-2026-42287?
As of now, there are no public exploits reported for CVE-2026-42287, but the vulnerability itself poses significant risk.